Security

Review Safety Controls In The App

Open Settings → Privacy and Data for data-sharing controls. Open Settings → Permissions for Safe Mode. Open Approvals for actions waiting on a person.

Session data sharing control, off by default

Overview

Neotask is built with security as a core principle. Every layer, from license activation to data storage to network communication, is designed to protect your data and prevent unauthorized access.

License Security

Two-Factor Authentication (TOTP)

Neotask supports optional (but recommended) two-factor authentication for dashboard access.

Encryption

Data at Rest

Data in Transit

Environment Secrets

Desktop App Security

Electron Hardening

Neotask applies strict Electron security settings to protect the desktop application:

Content Security Policy (CSP)

App Integrity

Network Security

Gateway Isolation

3-Strike Lockout

API Security

Authentication Methods

Method Used For Security Level
JWT Bearer Token Web dashboard, API calls Standard (90-day expiry)
License HMAC Desktop app operations High (per-device secret)
Session Grants Gateway operations Very High (10-min, HMAC-signed)
TOTP Dashboard login Additional factor

Rate Limiting

Endpoint Limit
Contact form 5 requests per 15 minutes
Login attempts 10 requests per 15 minutes
Analytics/tracking 30 requests per 60 seconds

Input Validation

Provider Key Security (BYOK)

When using Bring Your Own Key (BYOK) mode, Neotask applies additional safeguards to your API keys:

Provider Destination Controls

In hosted-credit mode, Neotask sends model requests only to the official HTTPS hosts assigned to the selected provider. A provider name cannot be paired with an arbitrary target host, and upstream redirects are blocked before they can carry a Neotask-managed or BYOK credential to another destination.

Custom provider base URLs are available only on direct BYOK gateway paths, where the user supplies the destination and credential. They are not accepted by the hosted-credit passthrough.

Safe Mode

The confirmation explains the wider access that becomes available before Safe Mode is disabled.

Safe Mode confirmation explaining the effect of disabling protection

Neotask includes a Safe Mode feature that provides an execution sandbox for agents:

Audit and Compliance

Approval records show the requested action and the controls available to the reviewer.

Approval detail with the requested action and review controls

Best Practices

  1. Enable TOTP on your dashboard for two-factor authentication.
  2. Download backup codes and store them securely.
  3. Set daily budgets to prevent unexpected charges.
  4. Use BYOK mode if you want full control over your API keys.
  5. Keep the app updated, as auto-updates include security patches.
  6. Review agent permissions periodically in Safe Mode settings.